On August 28, the California Legislature passed SB 690, which eliminates the private right of action under the pen register/trap-and-trace provision of the California wiretapping act (CIPA Section 638.51). Governor Newsom is expected to sign the bill into law.
The big question that everyone is asking is whether this will actually stem the tide of wiretapping litigation.
I'm not optimistic.
First, SB 690 leaves the traditional wiretapping provision – Section 631 – fully intact. Early versions of the bill included limitations on Section 631 claims. However, these were taken out of the bill before it passed.
Second, SB 690 has no impact on the federal wiretapping law (ECPA) or on other state wiretapping laws (e.g., Illinois, Pennsylvania, etc.).
Third, we are already seeing plaintiff firms assert alternative theories of liability-- e.g., under CDAFA (as my partner Matt blogged about here).
That said, SB 690 certainly throws a wrench in plaintiffs’ litigation strategy to date.
There’s a reason why so many plaintiff firms have embraced a pen register theory of liability, as opposed to claims under ECPA, CIPA Section 631, and CDAFA. The pen register provision prohibits the installation of a device or process that records routing or addressing information to a third party without the user’s consent. And it provides for $5,000 in statutory damages per violation. It has been relatively easy for plaintiffs to allege that tracking pixels allow third parties (e.g., TikTok or X/Twitter) to intercept users’ addressing information (e.g., IP addresses and device identifiers). Courts have issued mixed rulings on whether these allegations state a pen register violation. Plaintiff firms have been able to capitalize on this legal uncertainty—securing large numbers of settlements.
By contrast, there are more obstacles to alleging an ECPA, Section 631, or CDAFA violation. For example:
- ECPA is a one-party consent statute. While some courts have held that the crime-tort exception overrides one-party consent, these decisions are mainly in cases involving health or other sensitive data.
- Section 631 requires: (1) the interception of the contents of a communication; and (2) that the interception take place in transit. This requires a more detailed, individualized analysis of the data flows.
- CDAFA does not provide for statutory damages; plaintiffs need to prove that they suffered an “economic harm or loss”
Assuming that SB 690 is signed into law, plaintiffs will be forced to pivot to these other claims, or devise new creative legal theories. While SB 690 likely will not be the panacea that many hoped for, it will make these wiretapping claims more difficult to allege and prove.

/Passle/69ce4c141e42eea3bd4c2856/SearchServiceImages/2026-07-15-18-48-06-518-6a57d5e6200f7fa481c657de.jpg)
/Passle/69ce4c141e42eea3bd4c2856/SearchServiceImages/2026-07-07-01-34-36-951-6a4c57acfc4b15f7af797164.jpg)
/Passle/69ce4c141e42eea3bd4c2856/SearchServiceImages/2026-06-15-13-32-05-416-6a2ffed51b020180477f9222.jpg)
/Passle/69ce4c141e42eea3bd4c2856/SearchServiceImages/2026-06-11-16-03-22-933-6a2adc4a1c5f611a79955960.jpg)